All the supported OSes from Canonical have been affected by this problem

Jul 5, 2013 09:06 GMT  ·  By

In a security notice, Canonical published details about an OpenSSL vulnerability in its Ubuntu 13.04, Ubuntu 12.10, Ubuntu 12.04 LTS, and Ubuntu 10.04 LTS operating systems.

According to Canonical, applications could have been made to expose sensitive information over the network.

It has been discovered that TLS protocol 1.2, and earlier, could have encrypted compressed data without properly obfuscating the length of the unencrypted data, which allowed man-in-the-middle attackers to obtain plain text content.

For a more detailed description of the security problems, you can see Canonical's security notification.

The security flaws can be fixed if you upgrade your system(s) to the latest libssl1.0.0 package, specific to each distribution. To apply the update, run the Update Manager application.

In general, a standard system update will make all the necessary changes. A system restart will not be necessary to implement the changes.